Skip to main content
Back to Arizmic

Security

The security boundaries for the public website, local workstation data, user-selected providers, credentials, and future releases.

Last updated 2026-08-10

Arizmic is designed as local desktop software with explicit connections to supported external services. That architecture reduces the need to place core research projects in an Arizmic-operated cloud, but it does not remove the need for device security, careful credential handling, or provider review.

Local workstation boundary

Projects, imported datasets, strategies, notebooks, credentials, and research outputs remain on the user's computer by default. Users are responsible for operating-system updates, disk protection, local access controls, backups, and the security of devices and files they control.

Local-first is not an offline-only claim. A user may deliberately connect a data provider, hosted model, compatible endpoint, broker, licensing service, or update service.

Public website

The public website is hosted through Cloudflare, uses browser security headers and a restrictive script policy, and loads Cloudflare Web Analytics for aggregate website measurement. It must not be treated as a confidential workspace.

The site does not provide accounts, file uploads, checkout, downloads, or product activation. Do not place secrets, personal information, private research, or credentials in URLs or feedback messages.

Credentials and connected providers

Provider credentials should be limited to the permissions required for the intended workflow and stored using protections available on the user's system. Users should keep paper and live environments distinct, rotate exposed credentials, and review provider access regularly.

Hosted AI context is sent directly to the provider selected by the user rather than through an Arizmic-operated model relay. Each independent data, AI, broker, and connectivity provider controls its own systems, retention, security, and availability.

Releases and updates

No installer is distributed through the public pre-release website. When releases begin, platform, version, checksum, signing, notarization, and installer facts must come from verified release records rather than marketing copy.

The planned update check is limited to version, operating system, architecture, and update channel, without project contents or a stable tracking identifier. Product analytics and crash reporting are absent at initial release and require separate default-off controls if introduced later.

Report a security issue

Email support@arizmic.com with the subject [Security] Arizmic. Include a concise description, affected surface, steps to reproduce, and potential impact.

Do not access data that is not yours, degrade service, persist after confirming the issue, or include credentials in the report. Arizmic does not currently operate a public bug-bounty program or promise a payment for a report.

Current assurance level

Arizmic does not claim a penetration-test certification, SOC 2 report, ISO certification, formal bug-bounty program, or guaranteed remediation timeline. A future assurance claim will identify the scope and date of the work that supports it.

Security controls reduce risk; they do not guarantee that software, a provider, a device, or a network will be free of vulnerabilities or outages.